OSFI E-21 takes full effect September 1, 2026. Is your document vendor ready?

Every federally regulated Canadian financial institution must demonstrate operational resilience and third-party risk governance by the deadline — including where vendors store client data and how they document it. SideDrawer's Canadian data residency and continuous audit trails are a direct answer to what OSFI is now asking.

What is OSFI Guideline E-21?

OSFI Guideline E-21 is the operational resilience guideline issued by the Office of the Superintendent of Financial Institutions for federally regulated financial institutions in Canada — banks, insurance companies, trust companies, federal credit unions, and Canadian branches of foreign banks. It requires these institutions to demonstrate operational resilience and third-party risk governance, with full compliance required by September 1, 2026.

E-21 builds on OSFI Guideline B-10 (Third-Party Risk Management, in force since May 2024), which requires documented data handling provisions in every vendor contract, geographic data residency transparency, and continuous audit trails of third-party oversight. Some compliance guidance interpreting B-10 has also raised CLOUD Act exposure as a possible consideration for institutions using US-domiciled platforms — a point worth reviewing for any Canadian FRFI evaluating a US-hosted vendor.

Source: OSFI Guideline E-21 and OSFI Guideline B-10 (Office of the Superintendent of Financial Institutions)

Three requirements. Three direct answers.

OSFI B-10 names three specific examination points for third-party document and data vendors. Here is how SideDrawer answers each one.

B-10 Requirement

Documented data handling provisions in every vendor contract

SideDrawer provides documented data handling terms as a standard part of every institutional agreement — ready for OSFI examination review, not assembled after the fact.

B-10 Requirement

Geographic data residency transparency

SideDrawer offers Canadian data residency, with documented, verifiable answers to exactly where client data physically resides — the specific question OSFI examiners are now asking.

B-10 Requirement

Continuous audit trails of third-party oversight

Every document interaction — upload, access, share, and sign — is logged automatically. Compliance evidence exists as a byproduct of normal operation, not a manual reconstruction.

Where does your vendor's data actually reside?

Some compliance guidance interpreting OSFI B-10 has raised CLOUD Act exposure as a possible consideration for institutions using US-domiciled platforms. It may be worth asking any vendor handling client documents where that data physically lives.

US-Hosted Platforms

Questions Worth Asking

  • Jurisdiction can depend on where the vendor is domiciled
  • Data residency terms vary by vendor — worth confirming directly
  • A consideration some compliance teams are reviewing under B-10
SideDrawer

Canadian Data Residency

  • Data resides in Canada, with documented residency terms
  • Continuous audit trail on every document interaction
  • Aligned with OSFI B-10 examination requirements

The vault is what makes AI adoption safe

Shadow AI doesn't announce itself — it shows up as an employee pasting a client statement into an AI tool to summarize it faster. A structured document vault doesn't stop AI use. It controls which data AI can reach.

72%
of financial services employees use at least one unsanctioned AI tool
Source: Salesforce, 2024 global research
27.4%
of corporate data pasted into AI tools is classified as sensitive — up from 10.7% a year ago
Source: Cyberhaven, 2026 AI Adoption & Risk Report
67%
of users access AI via non-corporate accounts on corporate devices — outside enterprise data governance
Source: Verizon, 2026 Data Breach Investigations Report

Client documents in SideDrawer's vault cannot be accessed by unauthorized AI tools without passing through SideDrawer's governed access layer first.

SOC 2
Type II certified
Bank-grade encryption
150+
Financial services firms
deployed across North America
100%
Audit trail on every action
upload, access, sign, and share

Frequently Asked Questions

OSFI Guideline E-21 is the Office of the Superintendent of Financial Institutions' operational resilience guideline for federally regulated financial institutions in Canada. It requires banks, insurance companies, trust companies, federal credit unions, and Canadian branches of foreign banks to demonstrate operational resilience and third-party risk governance, with full compliance required by September 1, 2026.
OSFI E-21 requires full compliance from all federally regulated financial institutions by September 1, 2026.
Yes. E-21 is built on OSFI Guideline B-10 (Third-Party Risk Management, in force since May 2024), which requires documented data handling provisions in every vendor contract, geographic data residency transparency, and continuous audit trails of third-party oversight. Any vendor holding client documents on behalf of a federally regulated institution falls within this scope.
OSFI Guideline B-10 governs third-party risk management for federally regulated financial institutions and has been in force since May 2024. E-21 builds on B-10's requirements as part of its broader operational resilience framework, including data residency transparency. Some compliance guidance interpreting B-10 has also raised CLOUD Act exposure as a possible consideration for US-hosted platforms.
Yes. SideDrawer offers Canadian data residency with documented data handling provisions and a continuous audit trail on every document interaction, directly addressing the data residency transparency and third-party oversight requirements under OSFI B-10 and E-21.

The window closes September 1, 2026.

Talk to our team before your next OSFI examination cycle begins.